Major Crypto Heist: Kelp DAO Loses $292 Million in rsETH to Cross-Chain Exploit

A significant breach has occurred in the DeFi space, with an attacker successfully draining a substantial amount of rsETH from Kelp DAO's cross-chain bridge, sparking a wave of emergency responses and freezes across various lending platforms and protocols. The incident, which took place on Saturday at 17:35 UTC, saw the attacker exploit LayerZero's cross-chain messaging layer to trick the bridge into releasing 116,500 rsETH, worth roughly $292 million, to an attacker-controlled address. This represents approximately 18% of the token's circulating supply. The Kelp DAO protocol, a liquid restaking platform that utilizes EigenLayer to generate additional yield on user-deposited ETH, issues rsETH as a tradeable receipt. The drained bridge held the rsETH reserve backing wrapped versions of the token deployed across over 20 other blockchains. Following the successful drain, Kelp's emergency pauser multisig froze the protocol's core contracts 46 minutes later, at 18:21 UTC, in an attempt to mitigate further damage. Two subsequent attempts by the attacker to drain an additional 40,000 rsETH, valued at around $100 million, were reverted. The exploit has raised concerns among holders of rsETH on non-Ethereum deployments, as the drained reserve backing wrapped versions on every layer 2 blockchain has created uncertainty about the tokens' underlying value. This has led to a potential feedback loop, where panic redemptions on L2s may pressure the unaffected Ethereum supply, potentially forcing Kelp to unwind restaking positions to honor withdrawals. The fallout from the exploit has already been felt across the DeFi space, with Aave, SparkLend, and Fluid freezing their rsETH markets, and Lido Finance pausing further deposits into its earnETH product. The incident serves as a reminder of the ongoing risks and challenges faced by the DeFi sector, particularly in the context of cross-chain bridges and the potential for exploits. As the investigation into the incident continues, the focus will be on determining the root cause of the exploit and the potential for recovery of the stolen funds.